Creating and Managing Organizational Units (OUs)

Organizational units (OUs) are logical administrative units that can help you limit the scope of a domain. They can contain many types of objects, including those for computers, contacts, groups, printers, or users. Because they can also contain other OUs, you can build a hierarchy of OUs within a domain. You can also use OUs to delegate administrator privileges on a limited basis.

Creating an OU

You can create OUs in Active Directory Users And Computers. As long as you use an account that is a member of the Administrators group, you'll be able to create OUs anywhere in the domain. The only exception is that you cannot create OUs within the default containers created by Active Directory.

Note

Note that you can create OUs within the Domain Controllers container. This is possible because this container is created as an OU. Creating OUs within Domain Controllers is useful if you want to organize domain controllers.

To create an OU, follow these steps:

  1. Click Start, Programs or All Programs, Administrative Tools, and Active Directory Users And Computers. This starts Active Directory Users And Computers.

  2. By default, you are connected to your logon domain. If you want to create OUs in a different domain, right-click the Active Directory Users And Computers node in the console tree, and then select Connect To Domain. In the Connect To Domain dialog box, type the name of the domain to which you want to connect, and then click OK. Alternatively, in the Browse For Domain dialog box, you can click Browse to find the domain to which you want to connect.

  3. You can now create the OU. If you want to create a top-level OU (that is, an OU that has the domain container as its parent), right-click the domain node in the console tree, point to New, and then select Organizational Unit. If you want to create a lowerlevel OU, right-click the OU in which you want to create the new OU, point to New, and then select Organizational Unit.

  4. In the New Object–Organizational Unit dialog box, type a new name for the OU, as shown in Figure 36-12, and then click OK. Although the OU name can be any string of up to 256 characters, the best OU names are short and descriptive.

    Specify the name of the OU to create.

    Figure 36-12. Specify the name of the OU to create.

Setting OU Properties

OUs have properties that you can set to add descriptive information. This will help other administrators know how the OU is used.

To set the properties of an OU, double-click the OU in Active Directory Users And Computers. This displays the OU's Properties dialog box, as shown in Figure 36-13.

The OU properties dialog box.

Figure 36-13. The OU properties dialog box.

  • On the General tab, you can enter descriptive information about the OU, including a text description and address information.

  • On the Managed By tab, you can specify the user or contact responsible for managing the OU. This gives a helpful point of contact for questions regarding the OU.

  • On the COM+ tab, you can specify the COM+ partition of which the OU should be a member (if any).

  • On the Group Policy tab, you can create Group Policy Objects that specify a set of rules for resources in the OU. These rules control the working environment for computers and users.

Creating or Moving Accounts and Resources for Use with an OU

After you create an OU, you might want to place accounts and resources in it. In Active Directory Users And Computers you follow one of these procedures:

  • You create accounts in the OU, right-click the OU, point to New, and then select the type of object to create, such as Computer, Group, or User.

  • You move existing accounts or resources to an OU, and then select the account or resources in its existing container by clicking and holding the left mouse button. You can then drag the account or resource to the OU. When you release the mouse button, the account or resource is moved to the OU. Using Ctrl+Click or Shift+Click, you can select and move multiple accounts as well.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset